Fallos del tipo CWE-285

1592 resultados

Falha ou verificação incorreta de autorização

O software não valida adequadamente se quem está tentando acessar um recurso ou executar uma ação tem permissão para isso. O controle de acesso pode estar ausente, mal implementado ou bypassável, permitindo que um usuário acesse dados ou execute operações que não deveria.

Ejemplo

Um sistema bancário que verifica se o usuário está autenticado (logado), mas não valida se ele pode transferir dinheiro da conta de outro cliente. Ou uma API que exibe dados sensíveis porque só checou autenticação, não autorização por perfil.

Cómo mitigar

Implemente controles de autorização em todas as operações sensíveis: verifique não só quem é o usuário, mas também se ele tem direito àquele recurso específico. Use padrões como RBAC (papéis) ou ABAC (atributos), e aplique a verificação no servidor, nunca confie no cliente.

CVE-2025-3921HIGHPeproDev Ultimate Profile Solutions 1.9.1 - 7.5.2 - Missing Authorization to Limited Unauthenticated Arbitrary User Meta Update via handel_ajax_req FunctionEPSS 0.4%CVE-2025-10318MEDIUMJeecgBoot WebSocket Message sendWebSocketMsg improper authorizationEPSS 0.4%CVE-2026-12771LOWBerriAI litellm M2M JWT user_api_key_auth.py improper authorizationEPSS 0.4%CVE-2025-64523HIGHFileBrowser has Insecure Direct Object Reference (IDOR) in Share Deletion FunctionEPSS 0.4%CVE-2020-3539MEDIUMCisco Data Center Network Manager Authorization Bypass VulnerabilityEPSS 0.4%CVE-2026-61718MEDIUMbunkerweb: Read-only Web UI users can delete job cache files due to missing authorization on /cache/ routesEPSS 0.4%CVE-2024-39412MEDIUMAdobe Commerce | Improper Authorization (CWE-285)EPSS 0.4%CVE-2024-39407MEDIUMAdobe Commerce | Improper Authorization (CWE-285)EPSS 0.4%CVE-2024-39419MEDIUMA user without ship permissions can ship the ordersEPSS 0.4%CVE-2024-39405MEDIUMAdobe Commerce | Improper Authorization (CWE-285)EPSS 0.4%CVE-2022-29913MEDIUMThe parent process would not properly check whether the Speech Synthesis feature is enabled, when receiving instructions from a child procesEPSS 0.4%CVE-2024-6384MEDIUMBackup files may be downloaded by underprivileged users in MongoDB Enterprise ServerEPSS 0.4%CVE-2024-6840MEDIUMAutomation-controller: gain access to the k8s api server via job execution with container groupEPSS 0.4%CVE-2026-85055HIGHTwenty: Field-level read bypassEPSS 0.4%CVE-2025-9760MEDIUMPortabilis i-Educar Matricula API matricula improper authorizationEPSS 0.4%CVE-2026-40248HIGHfree5gc UDR improper path validation allows unauthenticated creation and modification of Traffic Influence SubscriptionsEPSS 0.4%CVE-2025-12283MEDIUMcode-projects Client Details System authorizationEPSS 0.4%CVE-2026-12799MEDIUMBerriAI litellm Incomplete Fix CVE-2025-0628 internal_user_endpoints.py ui_view_users improper authorizationEPSS 0.4%CVE-2025-4474HIGHFrontend Dashboard 1.0 - 2.2.7 - Missing Authorization to Authenticated (Subscriber+) Privilege Escalation via fed_admin_setting_form_function FunctionEPSS 0.4%CVE-2026-53515HIGHBetter Auth: Privilege escalation via SSO provider registration: missing admin role check in @better-auth/ssoEPSS 0.4%